[Dshield] Odd URL attempts

Schuyler, Peter Pschuyler at tycoint.com
Thu Jun 21 17:31:24 GMT 2007


Earlier today we caught someone from a China IP address sending some URL
requests with embeded Hex values. I caught the request packet, and was
wondering if someone from the list was able to tell exactly what they
were trying to accomplish.

Here's a sample request: 

	GET
/security<OD><OA><31><66><66><63><0D><0A>/tech_partners_video.jsp

The target site is running Apache on Linux.

Schuyler


More information about the list mailing list